Colombia Data Protection Law (Law 1581 of 2012)
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Ley 1581: Data Protection Authority and Sanctions (Title VII)
The Superintendence of Industry and Commerce (SIC), through a Delegatura for Personal Data Protection, exercises oversight to ensure compliance with the law.
- Awareness of SIC oversight + registration obligations
- No engagement with SIC requirements
The SIC ensures compliance, processes consultations/complaints, orders measures, conducts investigations, imposes sanctions, administers the National Database Registry (RNBD) and issues instructions.
- Procedures to respond to SIC investigations/orders
- No process for SIC requests
The SIC may impose fines up to 2,000 monthly minimum wages, suspension of activities, temporary/definitive closure of processing operations for sensitive-data violations.
- Penalty-exposure awareness
- Remediation tracking from SIC orders
- No awareness of sanction exposure
Ley 1581: Duties of Controllers and Processors (Title VI)
Controllers must guarantee rights, obtain authorization, keep data accurate, ensure security, handle consultations/complaints, update/rectify/delete on request, inform of breaches to the SIC, and comply with SIC instructions.
- Controller compliance program covering Art.17 duties
- Security + breach-notification to SIC
- Controller duties not implemented
Processors must guarantee data security, handle consultations/complaints, apply the controller's policies, update/rectify/delete on instruction, and register databases as required; bound by a transmission contract.
- Transmission contract with processors
- Processor security + rights-handling evidence
- No transmission contract / processor duties undefined
Ley 1581: General Provisions and Principles (Titles I-II)
Applies to personal data recorded in any database by public or private entities in Colombian territory or where Colombian law applies by international treaty, with stated exceptions (e.g. domestic/personal, journalistic, intelligence, financial-credit databases under their own regimes).
- Determination that processing is within Ley 1581 scope
- Mapping of any exempt databases
- Scope/exemptions not assessed
Defines key terms: Titular (data subject), Tratamiento (processing), Responsable (controller), Encargado (processor), Autorizacion (authorization), Base de Datos, Dato personal, Dato publico/privado/semiprivado.
- Data inventory using Ley 1581 categories
- Controller/processor role mapping
- Roles (Responsable/Encargado) not assigned
Processing is limited by the nature of the data; personal data (except public data) may not be available on the Internet or mass media unless access is technically controllable for authorized parties.
- Controls preventing public exposure of non-public personal data
- Personal data publicly accessible online
All persons involved in processing non-public data must guarantee confidentiality, even after the relationship ends.
- Confidentiality undertakings for personnel/processors
- No confidentiality obligations
Processing must serve a legitimate purpose under the Constitution and law, which must be informed to the data subject.
- Documented legitimate purpose per processing, communicated to data subjects
- Purpose undefined or not informed
Processing is a regulated activity that must comply with Ley 1581 and its implementing rules.
- Lawful-processing policy referencing Ley 1581 + Decreto 1377/2013
- Processing without a legal framework basis
Processing requires the prior, express and informed consent of the data subject; data may not be obtained or disclosed without authorization or a legal/judicial mandate.
- Prior express informed authorization records
- Processing without prior authorization
Data must be managed with the technical, human and administrative measures necessary to secure records against adulteration, loss, unauthorized or fraudulent access.
- Technical/administrative security measures for personal data
- No security measures
The data subject has the right to obtain, at any time and without restriction, information about the existence of data concerning them.
- Mechanism for data subjects to learn what data is held
- No transparency mechanism
Data must be truthful, complete, accurate, up to date, verifiable and comprehensible; partial, incomplete or misleading data processing is prohibited.
- Data accuracy/update procedures
- Inaccurate or partial data processed
Ley 1581: Registry, International Transfers and BCRs
Controllers must register their databases in the National Database Registry (Registro Nacional de Bases de Datos) administered by the SIC.
- RNBD registration records for all databases
- Databases not registered in the RNBD
Transfer of personal data to countries not providing adequate protection levels is prohibited, except: subject authorization; medical/health exchange; bank/stock transfers; treaties; legal/judicial cooperation; or SIC-declared adequacy.
- Transfer adequacy assessment / SIC declaration / subject authorization per recipient
- Transfers to non-adequate countries without an Art.26 basis
Transfers and transmissions within corporate groups may rely on binding corporate rules (normas corporativas vinculantes) authorized by the SIC.
- Approved binding corporate rules where relied upon
- Intra-group transfers without an authorized mechanism
Ley 1581: Rights and Conditions of Lawful Processing (Titles IV-V)
Authorization is not required for: information required by a public/administrative entity in legal exercise or by court order; public-nature data; medical/health emergencies; authorized historical/statistical/scientific processing; data related to civil registry.
- Assessment of Art.10 exceptions relied upon
- Exception claimed without basis
At or before collection the controller must inform the subject of the processing and its purpose, their rights, and the identity/contact of the controller (privacy notice / aviso de privacidad).
- Privacy notice (aviso de privacidad) covering Art.12 elements
- No privacy notice at collection
Personal data may be supplied only to the data subject/assignees, entities with legal/judicial authority, and third parties authorized by the subject or law.
- Disclosure-authorization controls
- Data disclosed to unauthorized parties
Data subjects (or assignees) may consult their personal data held by a controller/processor; the consultation must be answered within ten (10) business days (extendable by five).
- Consultation handling procedure + timeliness logs (10 business days)
- Consultations not answered within deadline
Data subjects may file complaints to correct, update, delete data or for breach of the law; complaints must be handled within fifteen (15) business days (extendable by eight).
- Complaint (reclamo) handling procedure + timeliness logs (15 business days)
- Complaints not handled within deadline
Data subjects may: know, update and rectify their data; request proof of authorization; be informed of the use of their data; lodge complaints with the SIC; revoke authorization and/or request deletion when processing breaches the law or constitution; and access their data free of charge.
- Procedure for know/update/rectify/revoke/delete requests
- Free-of-charge access mechanism
- Rights requests not supported
- Revocation/deletion not honored
Processing requires prior, express and informed authorization of the data subject (except Art.10 cases), obtained by any means that can later be evidenced.
- Authorization capture with evidentiary proof
- No demonstrable authorization
Ley 1581: Special Categories of Data (Title III)
Sensitive data affects the data subject's intimacy or whose misuse may cause discrimination: racial/ethnic origin, political orientation, religious/philosophical convictions, union/social/human-rights membership, health, sex life, and biometric data.
- Inventory flagging sensitive categories per Art.5
- Sensitive categories not identified
Processing sensitive data is prohibited except: explicit authorization; vital interest of an incapacitated subject; legitimate activities of a non-profit (political/religious/union) for its members; judicial proceedings; or historical/statistical/scientific purpose with de-identification measures.
- Explicit authorization for sensitive data
- Exception basis records
- De-identification for research use
- Sensitive data processed without explicit authorization or valid exception
Processing must respect the prevailing rights of children and adolescents; processing their data is proscribed except public-nature data; the State and educational entities must inform guardians of risks.
- Controls/age-gating for minors' data
- Guardian information measures
- Minors' data processed without safeguards
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Colombia Data Protection Law (Law 1581 of 2012) framework page.